Skip to content
View minanagehsalalma's full-sized avatar
🍒
Meow ?
🍒
Meow ?

Highlights

  • Pro

Block or report minanagehsalalma

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
minanagehsalalma/README.md

Mina Nageh Salama

Burp Suite Wireshark Firmware research Hack The Box

Mina Nageh Salama profile banner

Security researcher and engineer focused on web vulnerability research, browser-side investigations, malware analysis, and practical automation.

GitHub followers Public repositories Public stars LinkedIn Email

Operational Snapshot

Auto-refreshed daily via GitHub Actions. Last refresh: 2026-04-20 08:26 UTC

Current role
Red Team Researcher at Synack
Independent research
Since December 2020
Current study
MSc at University of Tuscia (UNITUS), Italy

Public CVEs Assigned CVE IDs Active research

Status note: All assigned 2026 CVE IDs are currently covered in a single public reference gist and can move into the public CVE section once broader publication catches up.

What I Work On

  • Web vulnerability research with clear reproduction steps, impact framing, and remediation notes
  • Browser-extension analysis, request/response inspection, and exploit-path validation
  • Router, Wi-Fi, and firmware security work
  • Python and JavaScript tooling to speed up testing, validation, and reporting
  • Write-ups and investigations that preserve technical detail without turning into noise

Selected Security Work

Public CVEs

Assigned CVE IDs

Assigned by MITRE in March 2026. Public reference gist is available.

All three currently share a single reference gist.

  • CVE-2026-34472: ZXHN H188A V6.0 unauthenticated credential disclosure via the web wizard, leading to admin, WLAN, and PPPoE credential exposure and auth bypass
  • CVE-2026-34473: ZXHN H-series multiple models unauthenticated denial of service via oversized application/x-www-form-urlencoded POST bodies against the management interface
  • CVE-2026-34474: ZXHN H298A and H108N sensitive data exposure through the web interface, leading to admin and WLAN credential disclosure

Other Findings And Analyses

  • Account takeover on OLX Middle East via password-reset logic abuse
  • Race condition in Medium's voting flow that enabled count manipulation
  • ShotBird analysis in March 2026: ownership-transfer to browser-based C2 chain, credential and form-data capture, and follow-on Windows credential targeting
  • Hack The Box work focused on systematic enumeration, common web vulnerabilities, and Linux privilege escalation

Selected Public Projects

Project Why it matters
Youtube-Downloader-Bookmarklet Strongest public repo by stars; a JavaScript bookmarklet with real usage traction.
huawei-dg8045-hg630-hg633-Config-file-decryption-and-password-decode Router-focused work that matches the security and firmware side of the profile.
burpsuite-custom-extension Current Python Burp extension work for response modification and testing workflows.
BookMarkletsWiki Practical browser tooling collected into one place.
Ubicast-Video-Downloader Small targeted JavaScript tooling with a clear one-click use case.
WIFI-Location-Locator-GUI Public Wi-Fi utility work that aligns with the network side of the profile.

Selected Gists

Gist Why it matters
ZTE ZXHN router vulnerabilities Public reference write-up for the assigned 2026 ZTE/ZXHN CVE IDs.
Export Chrome extensions inventory Practical PowerShell inventory/export tooling for browser-extension analysis and auditing.
Milanote Board to Markdown Useful browser automation work that turns visual boards into markdown output.
Reddit post exporter Tampermonkey-based structured export tooling with a clear LLM/data-prep use case.

Experience And Education

  • Red Team Researcher, Synack, Inc. | Remote | June 2025 to present
  • Independent Security Researcher | Bug bounty and crowdsourced platforms | December 2020 to present
  • MSc, University of Tuscia (UNITUS), Italy | 2025 to expected July 2027
  • BSc Computer Science, Thebes Academy, Cairo | October 2021 to May 2025

Toolbox

Skills

Pinned Loading

  1. youtube-to-article-images-gifs youtube-to-article-images-gifs Public

    YouTube to article pipeline with image and GIF extraction; Supports Gemini

    Python

  2. Zyxel-4-password-decrypter Zyxel-4-password-decrypter Public

    Reverse-engineered decryption tool for Zyxel Scheme ID 4/5 passwords. Recovers plaintext administrative credentials using static AES-192-CBC parameters.

    Python

  3. RevancedForChromeExtensions RevancedForChromeExtensions Public

    ReVanced-style patch generator and patcher for unpacked Chrome extensions. It creates a portable zip bundle describing file operations (add, delete, replace) and the payload bytes needed to reprodu…

    TypeScript 2

  4. Youtube-Downloader-Bookmarklet Youtube-Downloader-Bookmarklet Public

    A Javascript Bookmarklet That creates a menu for downloading YT Vids without needing any third party app nor site.

    JavaScript 49 5

  5. BookMarkletsWiki BookMarkletsWiki Public

    A curated collection of useful and fun bookmarklets to enhance your browsing experience.

    HTML 10 1

  6. huawei-dg8045-hg630-hg633-Config-file-decryption-and-password-decode huawei-dg8045-hg630-hg633-Config-file-decryption-and-password-decode Public

    Python 13 2